PT-2026-27115 · Nexxt Solutions · Nebula 300+
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nexxt Solutions Nebula 300+ versions prior to 12.01.01.38
Description
Administrative authentication material is stored in the
ecos pw cookie using a Base64-encoded format with a static suffix. Since Base64 is a reversible encoding scheme and the cookie lacks integrity protection, an attacker who obtains or derives this value can reconstruct or forge a valid administrative session to gain unauthorized access to the device.Recommendations
Update to a version newer than 12.01.01.37.
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nebula 300+